Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
Login/RegisterForumsMobile ForensicsLive ForensicsReviewsInterviewsJobsPapersNewsletterEventsTrainingBlogDownloads
Search Forensic Focus
Custom Search
Join, Subscribe, Share

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Main Menu
MY ACCOUNT
COMMUNITY
RESOURCES
MISC
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!

Computer Forensics Survey
Which of the following do you usually use for imaging evidence?




Results :: Polls

Votes: 33313
Comments: 0
Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!



Forensic Analysis of the Windows Registry

Page: 1/16
Lih Wern Wong
School of Computer and Information Science, Edith Cowan University
lihwern@yahoo.com

Abstract

Windows registry contains lots of information that are of potential evidential value or helpful in aiding forensic examiners on other aspects of forensic analysis. This paper discusses the basics of Windows XP registry and its structure, data hiding techniques in registry, and analysis on potential Windows XP registry entries that are of forensic values.

Keywords:

Windows registry, forensic analysis, data hiding


INTRODUCTION

Windows 9x/ME, Windows CE, Windows NT/2000/XP/2003 store configuration data in registry. It is a central repository for configuration data that is stored in a hierarchical manner. System, users, applications and hardware in Windows make use of the registry to store their configuration and it is constantly accessed for reference during their operation. The registry is introduced to replace most text-based configuration files used in Windows 3.x and MS-DOS, such as .ini files, autoexec.bat and config.sys. Due to the vast amount of information stored in Windows registry, the registry can be an excellent source for potential evidential data. For instance, windows registry contains information on user accounts, typed URLs, network shared, and Run command history. Aspects discussed in this paper are based solely on Windows XP (Service Pack 2) registry.


REGISTRY STRUCTURE

Figure 1 shows Windows registry logical view from Register Editor (Windows default register editor). Each folder in the left key pane is a registry key. The right panes show the key's value. Subkey is used to show the relationship between a key and the keys nested below it. Branch refers to a key and all its subkeys. Windows uses symbolic link (i.e. similar to file system's shortcut) to link a key to a different path which allows the same key and its values to appear at two different paths (Russinovich, 1999).

Figure 1: Windows Registry Logical View Key






Next Page (2/16) Next Page


User Info

Welcome Anonymous

Nickname

Membership:
Latest: baigents
New Today: 0
New Yesterday: 10
Overall: 10301

People Online:
Members: 2
Visitors: 9
Bots: 4
Staff: 0
Staff Online:

No staff members are online!
Computer Forensics Blog
· UK members - Can you HACK it?
· Message from Nick Furneaux
· New forum (Live and Network Forensics) and new moderator
· Interview with Graham Brown-Martin, Digital Safety Conference
· Interview with Lee Whitfield, Forensic 4cast
· Interview with Robert Botchek, President and Founder – Tableau, LLC
· Digital Safety Conference, 19th June 2009, London
· Two men guilty of student murders
· Interview with Dr Chris Pamplin, Editor – UK Register of Expert Witnesses
· Hoffmann Advanced Forensic Sessions, November

read more...
This site needs YOU!

Write for Forensic Focus
LINK TO US

OR
WRITE FOR US
OR
START A BLOG

Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: Australasian Centre for Policing Research Best Practice Guide
  6: PDA Forensic Tools:An Overview and Analysis
  7: HELIX incident response CD
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Forensics Plan Guide & Forensic Cookbook

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2009 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.